INNER CODE UNIT · Python
executable_basename
magicsword-io/LOLRMM · bin/generate_detections.py:17
def executable_basename(path):
"""Read an installation path, not a command line, on any host OS.
Preserve Sigma wildcards within filenames, but exclude directory patterns,
invalid Windows placeholder names, and arguments following an executable.
"""
if not isinstance(path, str):
return None
path = path.strip()
if len(path) >= 2 and path[0] == path[-1] and path[0] in "\"'":
path = path[1:-1]
if any(char in path for char in '"|') or re.search(r"\.exe\s", path, re.I):
return None
name = ntpath.basename(path)
if (
not name
or name.startswith("*")
or not name.lower().endswith(".exe")